logo

Dire Wolf Ransomware Comes Out Snarling, Bites Technology, Manufacturing

ID: 9efb9195-d10e-5feb-ac1b-ee2b2dfd0a4d

STIX ID: report--9efb9195-d10e-5feb-ac1b-ee2b2dfd0a4d

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2025-06-25

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trustwave SpiderLabs analyzed a newly emergent ransomware group dubbed "Dire Wolf" that has impacted 16 organizations across 11 countries; the actor uses double extortion with targeted, victim-tailored encryptors and a monthlong payment window, publishes proof-of-exfiltration on a leak site, and provides live-chat credentials to negotiate ransoms. The sample analyzed was a UPX-packed Golang binary that enforces a single-instance mutex (Global\direwolfAppMutex), disables Windows event logging and recovery features, terminates interfering processes/services, and encrypts files using Curve25519 and ChaCha20 while appending a .direwolf extension; defenders are advised to harden endpoints, patch critical vulnerabilities, and deploy detections for the observed defense-evasion and impact techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.